The EDPB's New Anonymisation Guidelines: A Turning Point for the Secondary Use of Health Data

The EDPB’s New Anonymisation Guidelines: A Turning Point for the Secondary Use of Health Data

On 7 July 2026, the European Data Protection Board (EDPB) published its long-awaited Guidelines 02/2026 on Anonymisation, providing the most comprehensive European guidance on anonymisation in over a decade.

For organisations working with health data, these guidelines represent more than an update to existing practice. They reflect a significant evolution in how anonymisation is understood under the GDPR – moving beyond simple identifier removal towards a demonstrable, risk-based assessment of re-identification.

The threshold for anonymity has evolved

The guidelines reaffirm an important principle: properly anonymised data falls outside the scope of the GDPR.

However, they also make clear that demonstrating anonymisation requires considerably more than removing names or replacing identifiers with pseudonyms. Instead, organisations are expected to assess whether individuals remain identifiable using means that are reasonably likely to be used as defined under Recital 26 of the GDPR. This involves taking into account both available technology and the context in which the data will be processed.

This reflects a broader shift towards evidence-based privacy processing. At VEIL.AI, this philosophy has long underpinned our approach to anonymisation: rather than relying solely on traditional de-identification techniques, we combine anonymisation with quantitative privacy risk assessment to evaluate whether re-identification remains realistically possible.

Context matters

Perhaps the most significant development is the EDPB’s recognition that anonymisation is inherently contextual. Rather than asking whether anyone could theoretically identify an individual, the guidelines ask whether the intended recipient could do so using means reasonably likely to be used. This reflects recent case law from the Court of Justice of the European Union and provides a more practical framework for organisations sharing health data for research and innovation.

For many collaborative research projects, this distinction is particularly important. Hospitals may retain identifiable patient records, while research partners receive datasets that are anonymous from their own perspective. The guidelines explicitly acknowledge that these perspectives may differ.

This is reflected in VEIL.AI’s deployment model, where anonymisation is performed within the data controller’s secure environment before data are shared with external collaborators, helping organisations preserve both privacy and data utility.

A new technical framework for anonymisation

The EDPB introduces a structured framework built around three questions:

  • Can individual records be isolated?

  • Can records be linked to other datasets?

  • Can meaningful information about an individual be inferred?

These three criteria form the basis for assessing whether a dataset can be considered anonymous. This development shifts the discussion away from individual identifiers towards the overall risk of re-identification.

For organisations working with complex health datasets, this provides a much more realistic way of evaluating privacy risks. Rather than asking whether identifiers have been removed, the focus becomes whether individuals could still be identified through combinations of attributes, external datasets or inference attacks. This risk-based thinking closely aligns with how modern anonymisation technologies, including those developed by VEIL.AI, evaluate disclosure risk.

The increasing importance of documentation

Another notable aspect of the guidelines is the emphasis on accountability. Controllers are encouraged to document the anonymisation methodology, any assumptions made, all testing as well as the evidence supporting the conclusion that the resulting data is anonymous. In practice, this means anonymisation is increasingly becoming an auditable process rather than a one-time technical operation.

This is particularly important for healthcare organisations participating in collaborative research projects, where demonstrating compliance can be just as important as achieving it. Producing transparent risk assessments and documenting anonymisation decisions will likely become an increasingly important part of responsible data governance.

Modern privacy risks are recognised

The guidelines also acknowledge developments that barely existed when the previous guidance was published in 2014. They explicitly discuss linkage attacks, membership inference, AI-assisted re-identification, synthetic data, and evolving re-identification techniques. Rather than assuming that a single anonymisation method is sufficient indefinitely, organisations are encouraged to consider how advances in technology may affect privacy risks over time.

For companies like VEIL.AI, the recognition that anonymisation is no longer simply about masking identifiers is critical. Going forward, anonymisation requires continuous evaluation of evolving privacy risks, particularly as AI makes sophisticated linkage and inference attacks increasingly accessible.

What does this mean for healthcare?

Secondary use of health data depends on striking the right balance between protecting patient privacy and enabling research. In other words, this means optimising the utility–privacy tradeoff. The updated EDPB guidance provides organisations with a clearer framework for achieving this balance.

Instead of asking whether identifiers have been removed, organisations should ask:

  • Have we assessed realistic re-identification risks?

  • Have we considered potential linkage to external datasets?

  • Can meaningful inferences still be drawn?

  • Can we demonstrate why our anonymisation is effective?

These are precisely the kinds of questions that modern anonymisation workflows should be able to answer. The emphasis is shifting from simply producing anonymised data to being able to demonstrate, with evidence, why the data can reasonably be considered anonymous.

Looking ahead

The EDPB’s new guidance signals an important change in the European privacy landscape: Rather than treating anonymisation as a simple technical exercise, it recognises it as a comprehensive process combining legal interpretation, statistical disclosure control, risk assessment and technical validation.

For organisations working with health data, this provides greater clarity – and an opportunity to adopt more robust, evidence-based approaches to enabling the safe secondary use of health data.

At VEIL.AI, we see these guidelines as an important step towards a more mature understanding of anonymisation. By placing demonstrable privacy risk assessment, contextual analysis and transparent documentation at the centre of anonymisation, the EDPB has reinforced principles that are essential for unlocking the value of health data while maintaining public trust.

Share this
Facebook
Twitter
LinkedIn
Ready to Transform Your Data?

Connect with our experts to discuss your needs.​

Subscribe to our newsletter